LIVE · cybersecurity feed
Live wire
8,539 reasons to rethink how vulnerabilities get patched'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2024-39943 · Operation CameraSwarm Compromised 14,000+ Dahua CamerasCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emergeOracle Critical Patch Update, August 2026 Security Update ReviewCVE-2026-65400 · Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
security

Researchers find a loophole that lets expired credit cards make unauthorized payments

A team from the University of Massachusetts Amherst has shown that a contactless credit card keeps working past its printed expiration date, even after the cardholder gets a replacement. They named it the Zombie Card attack and presented the findings at USENIX Security 2026. The question behind the loophole “This work is motivated by documented patterns of improper expired card handling. Although

zeroday.news ·

Researchers at the University of Massachusetts Amherst have identified a vulnerability, dubbed "Zombie Card," that allows expired contactless credit cards to be used for unauthorized payments. The team, led by Muhammad Taqi Raza, assistant professor in the Riccio College of Engineering, presented their findings at USENIX Security 2026. The issue stems from a disconnect in how various components of the payment ecosystem verify card validity.

The research was prompted by the observation that credit card accounts do not expire with the physical card, allowing refunds to be processed even after a card's printed expiration date. This led Raza to investigate whether an expired card could also initiate a payment. Working with Raja Hasnain Anwar and Gerard DeCunha, the team confirmed this was possible for certain card configurations.

The "Zombie Card" attack exploits a lack of effective integrity protection in some contactless payment systems. The researchers demonstrated a relay attack using two ordinary smartphones equipped with near-field communication (NFC) capabilities. One phone activates the expired card to extract its payment data, including the outdated expiration date. A second phone, linked via Wi-Fi, intercepts this data, modifies the expiration date to a future date, and then transmits it to a point-of-sale (POS) terminal. Anwar noted that an attacker does not need the correct future date, as almost any future date will suffice, and the expiration date is not cryptographically protected in the vulnerable systems, making it easy to alter.

The team found that Visa contactless transactions were susceptible to this man-in-the-middle tampering. In contrast, tests against Mastercard, American Express, and Discover configurations showed these systems rejected altered dates because their cryptographic checks incorporate the expiration data, which would be broken by tampering.

The behavior of the cardholder's bank also played a significant role. With one major US bank, the modified expired card successfully completed purchases of $1, $100, and $500 in lab tests, and also live retail and grocery purchases of $2.79 and $3.19. This bank's systems reportedly only confirmed the existence of the account and the active status of the card number, without verifying if the specific card instance and its expiration date were still on file. A second bank, however, consistently declined transactions using the same trick, prompting cashiers to request the replacement card.

A contributing factor to the vulnerability in Visa's Kernel 3 is that the field typically used to flag an expired card to the issuer is reset to all zeros before being sent, preventing the bank from seeing that the terminal's own check would have failed. Additionally, cards often carry a second expiration date embedded in their digital certificates, which can be valid well beyond the printed date to accommodate renewal periods.

The researchers also uncovered a related issue concerning card replacements. In their tests, a card that had not yet reached its printed expiration date but had been automatically replaced due to having less than three months of validity remaining continued to function alongside its replacement on the same account. This suggests that replaced cards are not reliably deactivated, similar to expired ones.

The researchers disclosed their findings to Visa and the affected banks in May and December 2025, providing a reproduction guide, transaction records, and a demo video. Visa acknowledged the report and stated it was being reproduced by their red team, but neither Visa nor the banks had confirmed a fix by the time of publication. No CVE has been assigned. The team withheld the relay code to prevent its misuse for fraud, instead publishing sanitized logs and protocol details.

Proposed solutions include binding the expiration date to a cryptographic check, similar to how rival payment networks operate, ensuring banks receive information about the terminal's own card validity checks, and requiring issuers to verify the specific card and expiration date on file rather than just the account number. The researchers advise cardholders to always destroy expired cards and to monitor transaction activity even on closed accounts.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

8,539 reasons to rethink how vulnerabilities get patched

The window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. Source: Rapi

ai

OpenAI confirms ChatGPT is down as logins and signups fail

ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]

ai

Smashing Security podcast #481: Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold stat

aicritical

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

ransomware

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]

cloud

Sakura Internet hack exposes data of up to 1.36 million accounts

Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]